generated from langchain-ai/integration-repo-template
-
Notifications
You must be signed in to change notification settings - Fork 18
Closed
Description
We have a mend scan issue reporting a vulnerability issue with requests package to be upgraded to 2.32.4 to resolve the issue. We see this is compatibility issue with this package to update. Can we have a patched version?
Apparently its an issue with ibm-watsonx-ai library which is required by langchain-ibm
Dependency cycle: langchain-ibm -> ibm-watsonx-ai -> ibm-cos-sdk -> ibm-cos-sdk-core (2.14.1) which is mandating requests library to be ">=2.32.0,<2.32.3"
Metadata
Metadata
Assignees
Labels
No labels